Title:
Dynamic .NET Compilation Via Csc.EXE
Status:
test
Description:Detects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
References:
-https://securityboulevard.com/2019/08/agent-tesla-evading-edr-by-removing-api-hooks/
-https://www.clearskysec.com/wp-content/uploads/2018/11/MuddyWater-Operations-in-Lebanon-and-Oman.pdf
-https://app.any.run/tasks/c6993447-d1d8-414e-b856-675325e5aa09/
-https://twitter.com/gN3mes1s/status/1206874118282448897
-https://github.com/redcanaryco/atomic-red-team/blob/b27a3cb25025161d49ac861cb216db68c46a3537/atomics/T1027.004/T1027.004.md#atomic-test-1---compile-after-delivery-using-cscexe
Author: Florian Roth (Nextron Systems), X__Junior (Nextron Systems)
Date: 2019-08-24
modified:2026-03-23
Tags:
- -'attack.stealth'
- -'attack.t1027.004'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
Image|endswith:
'\csc.exe'
selection_susp_location_1:
CommandLine|contains:
-':\Perflogs\'
-':\Users\Public\'
-'\AppData\Local\Temp\'
-'\Temporary Internet'
-'\Windows\Temp\'
selection_susp_location_2:
- CommandLine|contains|all:
- ':\Users\'
- '\Favorites\'
- CommandLine|contains|all:
- ':\Users\'
- '\Favourites\'
- CommandLine|contains|all:
- ':\Users\'
- '\Contacts\'
- CommandLine|contains|all:
- ':\Users\'
- '\Pictures\'
selection_susp_location_3:
CommandLine|re:
'(?:[Pp]rogram[Dd]ata|%(?:[Ll]ocal)?[Aa]pp[Dd]ata%|\\[Aa]pp[Dd]ata\\(?:[Ll]ocal(?:[Ll]ow)?|[Rr]oaming))\\[^\\]{1,256}$'
filter_main_programfiles:
ParentImage|startswith:
-'C:\Program Files (x86)\'
-'C:\Program Files\'
filter_main_sdiagnhost:
ParentImage:
'C:\Windows\System32\sdiagnhost.exe'
filter_main_w3p:
ParentImage:
'C:\Windows\System32\inetsrv\w3wp.exe'
filter_optional_chocolatey:
ParentImage:
-'C:\ProgramData\chocolatey\choco.exe'
-'C:\ProgramData\chocolatey\tools\shimgen.exe'
filter_optional_defender:
ParentCommandLine|contains:
'\ProgramData\Microsoft\Windows Defender Advanced Threat Protection'
filter_optional_ansible:
ParentCommandLine|contains:
-'JwB7ACIAZgBhAGkAbABlAGQAIgA6AHQAcgB1AGUALAAiAG0AcwBnACIAOgAiAEEAbgBzAGkAYgBsAGUAIAByAGUAcQB1AGkAcgBlAHMAIABQAG8AdwBlAHIAUwBoAGUAbABsACAAdgAzAC4AMAAgAG8AcgAgAG4AZQB3AGUAcgAiAH0AJw'
-'cAewAiAGYAYQBpAGwAZQBkACIAOgB0AHIAdQBlACwAIgBtAHMAZwAiADoAIgBBAG4AcwBpAGIAbABlACAAcgBlAHEAdQBpAHIAZQBzACAAUABvAHcAZQByAFMAaABlAGwAbAAgAHYAMwAuADAAIABvAHIAIABuAGUAdwBlAHIAIgB9ACcA'
-'nAHsAIgBmAGEAaQBsAGUAZAAiADoAdAByAHUAZQAsACIAbQBzAGcAIgA6ACIAQQBuAHMAaQBiAGwAZQAgAHIAZQBxAHUAaQByAGUAcwAgAFAAbwB3AGUAcgBTAGgAZQBsAGwAIAB2ADMALgAwACAAbwByACAAbgBlAHcAZQByACIAfQAnA'
condition:
selection_img and 1 of selection_susp_location_* and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Legitimate software from program files - https://twitter.com/gN3mes1s/status/1206874118282448897
-Legitimate Microsoft software - https://twitter.com/gabriele_pippi/status/1206907900268072962
-Ansible
Level:
medium